T09 · Insecure Skill Coding Practices
- Location
skill.js:3- Finding
Hardcoded Clash API Bearer Secret
- Content
View full analysis
Vulnerability Details
File Location:
skill.js, lines 3 and 13
Vulnerability Type: Hardcoded authentication credential
Risk Level: MediumVulnerable Code
js const secret = 'ff62c2da-1504-446b-986f-f13ba034e8a5';The credential is subsequently placed in the authorization header:
js headers: { 'Authorization': `Bearer ${secret}`, 'Content-Type': 'application/json' }Technical Analysis
The bearer secret protecting the Clash External Controller API is embedded directly in distributable source code. Anyone who can read the skill package, a copied archive, or source-control history can recover the credential without authentication.
The code sends requests exclusively to
127.0.0.1:61222, which limits exposure to entities able to reach the host-local controller. However, hardcoding still defeats credential confidentiality and enables an untrusted local user or process to authenticate to any controller instance configured with this secret. Exposure may become broader if port forwarding, container networking, or another local relay makes the controller reachable.Attack Path
- An attacker obtains read access to the skill package or its source history.
- The attacker extracts the bearer secret from
skill.js. - From a context capable of reaching the Clash controller on port
61222, the attacker submits requests withAuthorization: Bearer <extracted-secret>. - The controller accepts the attacker as an authenticated API client.
- The attacker invokes available Clash API operations to inspect or alter proxy configuration and routing.
Impact Assessment
Successful exploitation grants the access provided by the Clash External Controller API under the exposed credential. This can include reading proxy state and changing traffic-routing selections, such as switching between proxy groups and direct routing. The demonstrated skill operations modify
GLOBAL...[truncated 279 chars]- Remediation
View remediation
Remediation Suggestions
- Remove the bearer secret from
skill.jsand all distributable artifacts. - Rotate the exposed Clash controller secret because it must be treated as compromised.
- Load the credential at runtime from a protected environment variable, operating-system credential store, or user-owned configuration file.
- Fail closed when the credential is missing rather than using a bundled default.
- Restrict any credential file to the account running the skill and prevent it from being committed to source control.
- Continue binding the controller to
127.0.0.1and avoid exposing or forwarding its port to untrusted networks. - Add secret-scanning checks to development and release workflows to prevent recurrence.
- Remove the bearer secret from
